Method for determining a modular inverse, electronic device and associated computer programs.
The method employs masked multiplicative and additive masking techniques to protect modular inverse generation in RSA CRT algorithms, addressing side-channel attacks and maintaining cryptographic confidentiality.
Patent Information
- Application Number
- FR2024002513
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-13
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2044-03-13
AI Technical Summary
Existing solutions do not provide satisfactory protection against side-channel attacks during the generation of modular inverses in cryptographic processes, particularly in RSA CRT algorithms, which are crucial for preserving the confidentiality of private cryptographic elements.
A method for determining a modular inverse using masked multiplicative and additive masking techniques, involving the use of random multiplicative masks and masked modules, along with exact division calculations to protect against side-channel attacks, is implemented in an electronic device.
The method effectively secures the generation of modular inverses by masking operations, preventing information leakage and enhancing resistance to side-channel attacks, thus ensuring the confidentiality of private cryptographic elements.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for determining a modular inverse, electronic device and associated computer programs.
[0001] The present invention relates generally to the field of cryptographic processing using modular arithmetic.
[0002] It relates more particularly to a method for determining a modular inverse, a method for generating an RSA CRT key, as well as an associated computer program and cryptographic processing device.
[0003] Some cryptography algorithms, particularly asymmetric cryptography such as the RSA (Rivest-Shamir-Adleman) algorithm, use the principles of modular arithmetic. The generation of cryptographic keys, having public and private elements, is necessary prior to the encryption or signing of messages. The confidentiality of the private elements must be preserved.
[0004] The RSA CRT algorithm (for "Chinese Remainder Theorem" in English terminology) is a variant of T RSA algorithms which uses the Chinese Remainder Theorem to speed up calculations.
[0005] In RSA CRT, private elements include: - a prime number P, - another prime number Q, - a first decryption exponent equal to a secret exponent modulo the other prime number reduced by one, - a second decryption exponent equal to the secret exponent modulo the prime number reduced by one, - a modular inverse C of the other prime number modulo the prime number: C - Q1 mod P-
[0006] The observation of a processor implementing a key generation method can make it possible to detect information on the successively manipulated data and, after observing one or more implementations of the method, to deduce information on the processed value.
[0007] The generation of the modular inverse C must therefore be protected against such attacks, generally called side-channel attacks.
[0008] Unfortunately, existing solutions do not provide satisfactory protection for the generation of the modular inverse.
[0009] To overcome these drawbacks, the present invention proposes, according to a first aspect, a method for determining a modular inverse of a number Q in the ring of integers modulo a given modulo P, the number and the given modulo being prime numbers, the given modulo being masked as first parts of an initial masking, the method being implemented by an electronic device and the method comprising the following steps: - Determination, preferably by random drawing, of a first multiplicative mask and a second multiplicative mask which are not harmed and prime to each other, - Determination of another masked module by applying the first multiplicative mask to the given module P, - Determination of a masked number equal to the product of the second multiplicative mask and the number Q, - Determination of a multiplicative inverse of the other masked module then determination of an intermediate inverse D resulting from a multiplication of the multiplicative inverse of the other masked module by the first multiplicative mask modulo the masked number, - Determination of second parts of a modular additive masking of a dividend, the dividend having the value ( - D - P + 1 ) mod N with N a public module of value equal to P • Q, and the determination of each second part comprising the determination of a product of the intermediate inverse and of a third part distinct from the same preliminary masking of the given module, - Calculation of the exact division of the dividend by the number, the modular inverse being the result of the exact division, the dividend, the modular inverse and the number being manipulated in hidden form.
[0010] Other advantageous and non-limiting characteristics of the method according to the invention, taken individually or in all technically possible combinations, are the following: - the initial masking is a masking pami an additive masking, a modular additive masking, a multiplicative masking and a modular multiplicative masking; - preliminary masking is additive masking; - the third parts are the first parts; - the method further comprises a mask changing step during which the third parts of the preliminary masking of the given module are determined from the first parts of the initial masking of said given module or from the other masked module and the first multiplicative mask; - the determination of one and only one second part of the hidden dividend also includes an increase of 1 in the product determined modulo the public module; - exact division includes replacing modular additive masking of the dividend with additive masking; - calculating exact division manipulates the masked number and the second mask multiplicative, the second multiplicative mask being odd; - the method further comprises calculating the public modulus from the given modulus and the number.
[0011] According to a second aspect, the invention proposes a method for generating an RSA CRT key comprising a method as defined previously.
[0012] According to a third aspect, the invention proposes a computer program comprising instructions executable by a processor and adapted to implement a method as defined previously, when these instructions are executed by the processor.
[0013] This program may use any programming language, and be in the form of source code, object code, or code intermediate between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0014] At least a portion of the methods of the invention may be computer-implemented. Accordingly, the present invention may take the form of an all-hardware embodiment or an embodiment combining software (including firmware, resident software, microcode, etc.) and hardware aspects, all of which may be collectively referred to herein as a "block."
[0015] According to a fourth aspect, the invention proposes an electronic device for determining a modular inverse of a number Q in the ring of integers modulo a given module P, the number and the given module being prime numbers, the given module being masked in the form of first parts of an initial masking, and the electronic device comprising: - a multiplicative mask determination block configured to determine, preferably by random selection, a first multiplicative mask and a second multiplicative mask which are not harmed and prime to each other, - a block for determining another masked module configured to determine another masked module by applying the first multiplicative mask to the given module P, - a block for determining a masked number configured to determine a masked number equal to the product of the second multiplicative mask and the number Q, - an inversion block configured to determine a multiplicative inverse of the other masked module and then determine an intermediate inverse D resulting from a multiplication of the multiplicative inverse of the other masked module by the first multiplicative mask modulo the masked number, - a dividend determination block configured to determine second parts of a modular additive masking of a dividend, the dividend having the value ( - D • P + 1 ) mod N with N a public module of value equal to P • Q, and the determination of each second part including the determination of a product of the intermediate inverse and of a third part distinct from the same preliminary masking of the given module, - an exact division block configured to calculate the exact division of the dividend by the number, the modular inverse being the result of the exact division, the dividend, the modular inverse and the number being manipulated in hidden form.
[0016] This electronic device can be configured to implement each of the embodiment possibilities envisaged for the methods as defined previously.
[0017] Of course, the various features, variants and embodiments of the invention may be combined with each other in various combinations to the extent that they are not incompatible or mutually exclusive.
[0018] Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended figures which illustrate exemplary embodiments thereof which are not in any limiting nature.
[0019] In the figures:
[0020] [Fig. 1] schematically represents a preferred embodiment of a device electronics according to the invention;
[0021] [Fig.2] illustrates in the form of a flowchart the main stages of a comparison secured according to an implementation mode, for the implementation of the invention;
[0022] [Fig.3] illustrates in the form of a flowchart the main steps of a de termination of a modular inverse according to a first embodiment of the invention;
[0023] [Fig.4] illustrates in the form of a flowchart the main sub-steps of a step of calculation of exact division in masked form according to a first embodiment for the implementation of a method for determining a modular inverse according to the invention;
[0024] [Fig.5] illustrates in the form of a flowchart the main sub-steps of a step of calculation of exact division in masked form according to a second embodiment for the implementation of a method for determining a modular inverse according to the invention;
[0025] [Fig.6] illustrates in the form of a flowchart the main stages of a de termination of a modular inverse according to a second embodiment of the invention;
[0026] [Fig.7] illustrates in the form of a flowchart the main stages of a de termination of a modular inverse according to a third embodiment of the invention;
[0027] [Fig.8] illustrates in the form of a flowchart the main stages of a de termination of a modular inverse according to a fourth embodiment of the invention.
[0028] Unless otherwise indicated, elements common or similar to several figures bear the same reference signs and have identical or similar characteristics, so that these common elements are generally not described again for the sake of simplicity.
[0029] In the context of the present description, qualifiers “first”, “second”, “third”, “fourth”, “fifth”, “sixth” are only indicative to distinguish elements that they qualify, but do not imply an order between them.
[0030] [Fig.l] schematically represents an electronic device 2 comprising a processor 4 (for example a microprocessor), a storage entity 6, a random access memory 8 and a communication entity 10.
[0031] The RAM 8 and the storage entity 6 are each linked to the processor 4 so that the processor 4 can read or write data in the storage entity 6 and / or the RAM 8.
[0032] The storage entity 6 stores computer program instructions, some of which are designed to implement a method as described with reference to one of FIGS. 2 to 8, when these instructions are executed by the processor 4.
[0033] The storage entity 6 is for example a hard disk or a non-volatile memory, possibly rewritable, for example of the EEPROM type (for "Electrically Erasable and Programmable Read-Only Memory" according to the commonly used English term).
[0034] The RAM 8 can for its part store at least some of the elements (in particular a first multiplicative mask, a second multiplicative mask, first parts of an initial masking, another masked module, a masked number, a multiplicative inverse, an intermediate inverse, third parts of a preliminary masking, second parts of a modular additive masking of a dividend, and a modular inverse as described with reference to at least one figure among figures 2 to 8) manipulated during the various processing operations carried out during one of the methods described below.
[0035] In the remainder of the description, memory is any one of the storage entity 6 and the RAM 8.
[0036] The electronic device 2 also comprises several blocks (not shown).
[0037] Typically, the electronic device 2 comprises a block for determining multiplicative masks, a block for determining another masked module, a block for determining a masked number, an inversion block, a block for determining a dividend and an exact division block.
[0038] The electronic device 2 may further comprise a block for determining a public module and / or a masking change block and / or a key generation block.
[0039] These blocks can in practice be realized by a combination of hardware elements and software elements.
[0040] Each block has a functionality described in one of the methods according to the invention and described below with reference to Figures 2 to 8. Thus, for each block, the electronic device 2 stores, for example, software instructions executable by the processor 4 of the electronic device 2 in order to use a hardware element (for example a communication entity or a memory) and thus implement the functionality offered by the block.
[0041] According to one possible embodiment, the computer program instructions stored in the storage entity 6 have for example been received (typically from a remote computer) during an operating phase of the electronic device 2 prior to the methods described with reference to FIGS. 2 to 8.
[0042] The communication entity 10 is connected to the processor 4 so as to allow the processor 4 to receive data from another electronic device (not shown) and / or to transmit data to another electronic device (not shown). In certain embodiments, the processor 4 can thus receive data L from the other electronic device, for example computer program instructions and / or input data, and / or transmit output data. An input data is for example a message that the electronic device 2 must sign using an RSA CRT key comprising a modular inverse generated with a method as described with reference to FIGS. 2 to 8. An output data is for example the result of said signature.
[0043] The electronic device 2 can take many forms (not shown).
[0044] According to a first example, the electronic device is a smart card, such as an identity card, a bank card or a universal integrated circuit card (also known as a UICC card for “Universal Integrated Circuit Card” in English terminology).
[0045] In this case, the communication entity 10 comprises, for example, contacts flush with one face of the smart card. Alternatively, the communication entity 10 could be produced by a contactless communication block. Generally, the communication entity 10 may be a wired or wireless communication block with another electronic entity.
[0046] According to a second example, the electronic device is a secure element, such as a secure microcontroller, which is integrated into another electronic device, typically a communication terminal or a car.
[0047] According to other examples, the electronic device is a USB key, a telephone mobile, a personal computer, a server or an identity document, such as an e-passport.
[0048] As will be seen later, the electronic device 2 is configured to determine a modular inverse of a number Q in the ring of integers modulo a given modulo P, the number and the given modulo being prime numbers, and the given modulo being masked in the form of first parts of an initial masking. The electronic device 2 may further be configured to generate an RSA CRT key comprising the modular inverse thus determined.
[0049] According to a first example, a quantity A is additively masked on the integers with n shares if it is given in the form of n quantities Ai, ... ,An such that the following equation is satisfied on the integers: A{ + ■ ■ ■ + An = A . In this example, the quantity A is said to be masked in the form of n parts Ai, ... ,An of an additive masking.
[0050] According to a second example, a quantity A is masked additively modulo a quantity B with n shares if it is given in the form of n quantities Ai, ... ,An such that the following equation is satisfied: Ax + ■ ■ ■ + An = A mod B . In this example, the quantity A is said to be masked in the form of n parts Ai, ... ,An of a modular additive masking of modulo B.
[0051] According to a third example, a quantity A is multiplicatively masked on the 2-part integers if it is given in the form of 2 quantities AbA2 such that the following equation is satisfied: A ■ A2 = A], In this example, the quantity A is said to be masked in the form of 2 parts AbA2 of a multiplicative masking.
[0052] According to a fourth example, a quantity A is masked multiplicatively modulo a quantity B with 2 shares if it is given in the form of 2 quantities AbA2 such that the following equation is satisfied: A • A2 = Aj mod B. In this case, the inverse of the quantity A2 modulo the quantity B is well defined. In this example, the quantity A is said to be masked in the form of 2 parts AbA2 of a modular multiplicative masking of modulo B.
[0053] Multiplicative masking with n shares and modular multiplicative masking with n shares, n being greater than or equal to 3, are other possible examples but are not preferred in the context of an RSA CRT algorithm.
[0054] The initial masking may be a masking, an additive masking, a modular additive masking, a multiplicative masking, and a modular multiplicative masking.
[0055] In the embodiments of the invention described below with reference to Figures 3 to 8, the sum of n parts Ab ... ,An of a modular additive masking of a quantity A can be securely compared with another quantity B.
[0056] [Fig.2] illustrates in the form of a flowchart the main steps of a secure comparison according to an implementation mode for the implementation of the invention. More precisely [Fig.2] illustrates the main steps of a secure comparison of a sum of n parts Ab ... ,An of a modular additive masking of a quantity A and another quantity B.
[0057] The size of quantity A is a bits.
[0058] The secure comparison is here implemented by the electronic device 2 due to the execution of the computer program instructions stored in the storage entity 6 as indicated above.
[0059] According to a step of determining a random number (step E2), the processor 4 determines a random number F by random drawing, that is to say by truly random drawing or by pseudo-random drawing, in a closed interval having a lower limit of value 0 and an upper limit of value 2a+0 - 1 with o a security integer. The security integer preferably has a non-zero value, for example 80.
[0060] The secure comparison then comprises a step of calculating a first intermediate data item (step E4), during which the processor 4 calculates a first intermediate data item Gi as follows: Gf = Ai + F.
[0061] The secure comparison then comprises a step of initializing an index (step E6), during which the processor 4 initializes an integer i to the value 2.
[0062] The secure comparison then comprises a step of updating the first intermediate data (step E8), during which the processor 4 updates the first intermediate Gi as follows: Gj = G । + Ab
[0063] The processor 4 then determines, in a test step (step E10), whether the integer ia reaches the value n.
[0064] If not, the integer i is incremented by 1 in an incrementation step (step E12) and the processor 4 loops to the step of updating the first intermediate data (step E8).
[0065] Thus the implementation of the secure comparison implements n -1 iterations of the step of updating the first intermediate data (step E8).
[0066] If yes at the test step (step E10), the processor 4 calculates, at a step of calculating a second intermediate data item (step E14), a second intermediate data item G2 as follows: G2 = B + F.
[0067] The secure comparison then comprises another test step (step E16), during which the processor 4 determines whether the first intermediate data is strictly less than the second intermediate data. During this other test step, the processor 4 can directly compare the first intermediate data to the second intermediate data.
[0068] If the first intermediate data is strictly less than the second intermediate data, this indicates that the result of the sum of the n parts Ai, ... ,An of the modular additive masking of the quantity A is strictly less than the other quantity B.
[0069] After the last iteration of the step of updating the first intermediate data (step E8), the first intermediate data has the value F + / . A, = F + A' "1=1 1
[0070] During the other test step, determining whether the first intermediate data is strictly less than the second intermediate data therefore amounts to determining whether F + A is strictly less than F + B, that is to say determining whether A is strictly less than B. However, the quantity A is not manipulated as such during this step and the other steps of the secure comparison, which preserves the confidentiality of the quantity A. The random element F makes it possible to ensure the confidentiality of the quantity A.
[0071] A person skilled in the art will understand that the steps of the secure comparison can be executed in other orders provided that each step has the elements necessary for its execution.
[0072] For example, the step of calculating a second intermediate data item (step E14) can be executed before the step of calculating a first intermediate data item (step E4) or before the step of initializing an index (step E6) or before the step of updating the first intermediate data item (step E8), but after the step of determining a random number (step E2).
[0073] The secure comparison described with reference to [Fig.2] executes the turns, i.e. the iterations, of the loop with an index that increments at each turn. Those skilled in the art will understand that the index of the loop can be managed differently as long as all the values of the index are traversed by executing the turns of said loop.
[0074] Typically, the method may be adapted to perform the n - 1 iterations of the step of updating the first intermediate data (step E8) in a different order, each iteration using a different value of the integer, between 2 and n. For example, the person skilled in the art may initialize the integer with the value n in the index initialization step (step E6), replace the incrementation step (step E12) with a decrementing step which decrements the integer i by 1, and determine in the test step (step E10) whether the integer ia reaches the value 2.
[0075] Those skilled in the art will also understand that the implementation of the step of calculating a first intermediate data item (step E4), and the implementations of the step of updating the first intermediate data item (step E8), can be managed differently to obtain the final value of the first intermediate data item, by summing each part of the modular additive masking of the quantity A and the random element F, the random element F being added to the current value of the first intermediate data item before all the parts of the modular additive masking are added.
[0076] [Fig.3] illustrates in the form of a flowchart the main steps of a method for determining a modular inverse according to a first embodiment of the invention.
[0077] The method of [Fig.3] aims to determine a modular inverse of a number Q in the ring of integers modulo a given module P, the number and the given module being prime numbers, and the given module being masked in the form of n first parts of an initial masking with n an integer strictly greater than one. The initial masking is here an additive masking.
[0078] The method of [Fig. 3] is here implemented by the electronic device 2 due to the execution of the computer program instructions stored in the storage entity 6 as indicated above.
[0079] The size of the given module P is p bits and the size of the number Q is q bits. For example pa for value 1024 and qa also for value 1024. Note however that p can have a different value from that of q.
[0080] According to a step of determining multiplicative masks (step S2), the processor 4 determines a first multiplicative mask R and a second multiplicative mask S which are not harmed and prime to each other.
[0081] The first multiplicative mask R has a size r, respectively the second multiplicative mask S has a size s, which is preferably at least the size of a word.
[0082] The word is also called a machine word. The word is a basic unit manipulated by the processor 4. The size of a word is for example 8 bits, 16 bits, 32 bits, 64 bits or 128 bits.
[0083] The size r of the first multiplicative mask R, respectively the size s of the second multiplicative mask S, is for example 80 bits.
[0084] The size r of the first multiplicative mask R may be different from the size s of the second multiplicative mask S.
[0085] Preferably, the size r of the first multiplicative mask R and the size s of the second multiplicative mask S are identical.
[0086] The determination of the first multiplicative mask R and of the second multiplicative mask S is preferably by random drawing, that is to say by truly random drawing or by pseudo-random drawing.
[0087] Typically, the processor 4 draws a first random number uniformly in a closed interval having a lower bound of value 1 and an upper bound of value 2S-1, the second multiplicative mask being the first random number. Then the processor 4 draws a second random number uniformly in a closed interval having a lower bound of value 1 and an upper bound of value 2r-l and repeats this operation until the greatest common divisor of the first random number and the second random number is equal to 1. The first multiplicative mask is the second random number when the greatest common divisor common of the first random number and the second random number is equal to 1.
[0088] According to an implementation variant, the second multiplicative mask may have been recorded in a memory of the electronic device 2 during an operating phase of the electronic device 2 prior to the method described here. The determination of the second multiplicative mask S is then by reading a memory of the electronic device 2. To determine the first multiplicative mask, the processor 4 can draw a random number uniformly in the closed interval having the lower limit of value 1 and the upper limit of value 2r-l, and repeat this operation until the greatest common divisor of the second multiplicative mask and the second random number is equal to 1. The first multiplicative mask is the second random number when the greatest common divisor of the second multiplicative mask and the second random number is equal to 1.
[0089] The method then comprises a step of determining another masked module (step S4), during which the processor 4 determines another masked module P(R) by applying the first multiplicative mask R to the given module P.
[0090] Typically, processor 4 calculates the other hidden module P(R) as follows: P <R) — ( P • R ) avec 'CS Premières parties.
[0091] According to a step of determining a masked number (step S6), the processor 4 determines a masked number Q(S) equal to the product of the second multiplicative mask S and the number Q.
[0092] The masked number can be determined by reading a memory of the electronic device electronic device 2, for example if the masked number has been previously determined then stored in the storage entity 6. This implementation can be advantageous if the second multiplicative mask has also been recorded in a memory of the electronic device 2 during an operating phase of said electronic device 2, prior to the method described here.
[0093] The masked number can be determined by calculation, for example if the number Q is masked as fourth parts of another initial masking, the fourths parts having been previously determined then stored in the memo entity 6. The other initial masking can be a masking among an additive masking, modular additive masking, multiplicative masking and multi masking modular plicative.
[0094] Typically, when the other initial masking is an additive masking with m shares, the processor 4 calculates the masked number Q(S) as follows: Qts^Ç / QjS) with Qj the fourth parts.
[0095] Preferably, the other initial masking is an additive masking with n shares, i.e. m is equal to n.
[0096]
[0097]
[0098]
[0099]
[0100]
[0101] The method then comprises a step of determining a multiplicative inverse (step S8) during which the processor 4 determines a multiplicative inverse P(R) 1 of the other masked module, typically by calculation from the other masked module P(R). The method continues with a step of determining an intermediate inverse (step S10) during which the processor 4 determines an intermediate inverse D resulting from a multiplication of the multiplicative inverse of the other masked module by the first multiplicative mask modulo the masked number. Typically the processor 4 calculates the intermediate inverse as follows: p = (P(R)) ' R mod Q^- The method then comprises a step of determining second parts of a modular additive masking of a dividend (step S12), during which the processor 4 determines second parts of a modular additive masking of a dividend, the dividend having the value ( - D • P + 1 ) mod N with N a public module of value equal to P • Q, and the determination of each second part comprising the determination of a product of the intermediate inverse and a third distinct part of the same preliminary masking of the given module. Typically, for any i ranging from 1 to n, processor 4 computes a second part T; of a modular additive masking of a dividend T as follows: T; = - D • Pj + Hj mod N such that y11 pj mod N — 1 ' ^In this example, the ^=1 i third parts are the first parts. In other words, the preliminary masking is the initial masking. The determination of each second part T; therefore includes the determination of a product D • Pj of the intermediate inverse D and a distinct third part P; of the same preliminary masking of the given module P, that is to say of the preliminary masking of the given module P. The modular additive masking of the dividend is here a modular additive masking of module N. Preferably, for one and only one value of i, H; is 1 and for the other values of i, H; is zero. In this case, the determination of one and only one second part of the hidden dividend further includes an increase of 1 of the product determined modulo the public module. The process is therefore more efficient because it limits the operations necessary to determine the dividend.
[0102] The public module N may have been recorded in a memory of the electronic device 2 during an operating phase of the electronic device 2 prior to the method described here.
[0103] If the public modulus N is not available, the method can calculate the public modulus from the given modulus and the number.
[0104] According to a first example, the processor 4 calculates the public modulus N as follows: 2 — Y111 ( p.. Q ) then N = Z / S with Z an intermediate result. Sum of the products Pj • Q(s), i ranging from 1 to n, allows preserving the confidentiality of the given module P.
[0105] According to a second example, if the number Q is masked in the form of m fourth parts of an additive masking, the fourth parts having been previously determined then stored in the storage entity 6, the processor 4 calculates the public module N as follows: p. Q jj • Sum n ' m products Pi • Qj, i ranging from 1 to n and j ranging from 1 to m, allows to preserve the confidentiality of the given module P and the number Q.
[0106] The method then comprises a step of calculating the exact division of the dividend by the number (step S14) during which the processor 4 calculates the exact division of the dividend by the number, the modular inverse being the result of the exact division, the dividend, the modular inverse and the number being manipulated in masked form.
[0107] A person skilled in the art will understand that the steps of the method for determining a modular inverse described with reference to [Fig.3], can be executed in other orders to the extent that each step has the elements necessary for its execution.
[0108] According to one example, the step of determining a masked number (step S6) can be executed before the step of determining another masked module (step S4) and after the step of determining multiplicative masks (step S2).
[0109] According to another example, the step of determining a multiplicative inverse (step S8) can be executed before the step of determining a masked number (step S6) and after the step of determining another masked modulus (step S4).
[0110] [Fig.4] illustrates in the form of a flowchart the main sub-steps of the step of calculating the exact division of the dividend by the number (step S14) according to a first embodiment.
[0111] In this first embodiment of the step of calculating the exact division, - the masked number Q(S) is the masked form of the number manipulated to carry out the exact division; and - the modular inverse is manipulated in the form of n fifth parts Ci, ... ,Cn of an additive masking.
[0112] According to a mask change sub-step (sub-step SS2), the processor 4 replaces the modular additive masking of modulus N of the dividend with an additive masking.
[0113] During this sub-step, the processor 4 replaces the n second parts of the Tb ... ,Tn modular additive masking of modulus N of the dividend by n sixth parts Eb ... ,En of an additive masking on the integers of said dividend.
[0114] Typically, processor 4 draws n-1 third random values E2, ... , uniformly in a closed interval having a lower bound of value 0 and an upper bound of value 2^1 - 1, then processor 4 initializes a data Ei as follows: Ej = T(. Then, for each i ranging from 2 to n, processor 4 updates the data Ei as follows: Ej = E j - Ej. Then, for each i ranging from 2 to n, processor 4 updates the data Ei as follows: Ej = Es + Tj. Finally, for each i ranging from 2 to n, if T j + ■ ■ ■ + Tn is a value strictly less than ( i - 1 ) • N, processor 4 updates the data Ei as follows: Ej = E1 - N.
[0115] The processor therefore obtains n sixth parts EH ... ,En from the n third parts TH ... ,Tn.
[0116] Subtracting at least one third random Ej from the data Ei before adding the n -1 third parts T2, ... ,Tn to the data El, makes it possible to preserve the confidentiality of the dividend.
[0117] The comparisons of Tj + ■ ■ ■ + Tn and ( i - 1 ) • N are made in a secure manner, for example according to the embodiment described above with reference to [Fig.2].
[0118] The exact division calculation step then comprises a dividend randomization sub-step (sub-step SS4), during which the processor 4 randomizes each sixth part of the masked dividend by applying the second multiplicative mask to the sixth part concerned. Typically, for any i ranging from 1 to n, the processor 4 performs a calculation as follows: Ej = E, • S.
[0119] Each sixth part E; can be decomposed into one or more word(s) E;[j] of rank j, j representing the weight of the word concerned and E;[0] being the word of lowest weight of the sixth part E;.
[0120] Similarly, - the masked number Q(S) can be decomposed into one or more word(s) Q(S)[j] of rank j, j representing the weight of the word concerned and Q(S)[0] being the word with the lowest weight of the masked number Q(S); and - for any i ranging from 1 to n, the fifth part C; of the modular inverse can be decomposed into one or more word(s) C;[j] of rank j, j representing the weight of the word concerned and C;[0] being the word of lowest weight of the fifth part C;.
[0121] Each fifth part Q of the modular inverse is broken down into w words, w having the value defined as follows: w = (p + k- l) > b with k = 2b, k being the word size manipulated by the processor 4. As already described, the size k of a word is for example 8 bits, 16 bits, 32 bits, 64 bits or 128 bits. For example if k is 8, b is 3.
[0122] In the present disclosure, the notation A > a denotes the largest integer less than or equal to A / 2a-
[0123] The step of calculating the exact division then comprises a sub-step of calculating the inverse of the inverse of the least significant word of the masked number Q(S) (sub-step SS6) during which the processor 4 calculates an inverse U modulo M a power of 2, of the inverse of the least significant word of the masked number Q(S). The processor 4 therefore obtains the inverse U whose value is defined as follows: U - ( - mod M' Typically, M has a value of 2k, where k is the word size
[0124]
[0125]
[0126] handled by processor 4. The calculation of an inverse modulo a power of 2 can be done according to techniques known to those skilled in the art, for example according to the technique described at the end of section 4 of the document “Tudor Jebelean: An Algorithm for Exact Division. J. Symb. Comput. 15(2): 169-180 (1993)”. The exact division calculation step then includes a sub-step of initializing a first index (sub-step SS8) during which the processor 4 initializes an integer j to the value 0. The step of calculating the exact division then includes a sub-step of initializing a second index (sub-step SS 10) during which the processor 4 initializes an integer i to the value 1.
[0127] The step of calculating the exact division then comprises a sub-step of calculating a fifth part word (sub-step SS 12), during which the processor 4 calculates the word of rank j of the fifth part C; of the modular inverse as follows: çj j] = EjO] - U mod 2k- As already described, k is the word size handled by processor 4.
[0128] The step of calculating the exact division then comprises a sub-step of updating a sixth part (sub-step SS 14) during which the processor 4 updates the sixth part E; as follows: g, _ (e- _ Q . • C [ j] ) > k-
[0129] The processor 4 then determines, in a first test sub-step (step SS 16), whether the integer ia reaches the value n.
[0130] If not, the integer i is incremented by 1 in a first incrementation sub-step (sub-step SS20) and the method loops to the sub-step of calculating a fifth part word (sub-step SS 12).
[0131] If yes in the first test substep (substep SS16), the processor then determines, in a second test substep (substep SS 18) whether the integer ja reaches the value w - 1.
[0132] If not in the second test sub-step, the integer j is incremented by 1 in a second increment sub-step (sub-step SS22) and the method loops to the sub-step of initializing a second index (sub-step SS 10) to perform a next round.
[0133] Thus, the method implements n ' w sub-steps of calculating a fifth part word (sub-step SS 12) and n ' w sub-steps of updating a sixth part (sub-step SS 14).
[0134] If yes in the second test sub-step (sub-step SS18), the step of calculating the exact division of the dividend by the number (step S14) ends.
[0135] In this first embodiment of the exact division calculation step, the masked number Q(S) is the masked form of the number that is manipulated to perform the exact division. The exact division calculation thus manipulates the masked number Q(s) and the second multiplicative mask S. The method is thus more efficient because it limits the operations necessary for calculating the exact division.
[0136] For this first embodiment of the exact division calculation step, the second multiplicative mask must be odd. The second odd multiplicative mask makes it possible to secure the method against side channel attacks.
[0137] A person skilled in the art will understand that the sub-steps of the exact division calculation step can be executed in other orders to the extent that each sub-step has the elements necessary for its execution.
[0138] According to an example, the sub-step of calculating the inverse of the opposite of the least significant word of the masked number Q(S) (sub-step SS6) can be executed before the sub-step of randomizing the dividend (sub-step SS4) and / or the sub-step of changing the mask (sub-step SS2).
[0139] According to another example, the sub-step of initializing a first index (sub-step SS8) can be executed before the sub-step of calculating the inverse of the opposite of the least significant word of the masked number Q(S) (sub-step SS6) and / or the sub-step of randomizing the dividend (sub-step SS4) and / or the sub-step of changing the mask (sub-step SS2).
[0140] The embodiment of the exact division calculation step, described with reference to [Fig.4], executes the turns, i.e. the iterations, of each loop with an index that increments at each turn. Those skilled in the art will understand that the index i can be managed differently as long as all the values of the index i are traversed by executing the turns of the loop concerned.
[0141] Typically the exact division calculation step can be adapted to perform the n' w sub-steps of updating a sixth part (sub-step SS 14) in a different order, each iteration using a different value of the pair of integers i,j. For example, the person skilled in the art can initialize the integer i with the value n in the sub-step of initializing a second index (sub-step SS10), initialize the integer j with the value 0 in the sub-step of initializing a first index (sub-step SS8), replace the first increment sub-step (sub-step SS20) with a first decrement sub-step which decrements the integer i by 1, determine in the first test substep (substep SS16) whether the integer ia reaches 1, and determine in the second test substep (substep SS18) whether the integer ja reaches w- 1.
[0142] [Fig.5] illustrates in the form of a flowchart the main sub-steps of the step of calculating the exact division of the dividend by the number (step S14) according to a second embodiment.
[0143] In this second embodiment of the step of calculating the exact division, - the number is manipulated in the form of a plurality of parts of an additive masking; - the modular inverse is manipulated in the form of n fifth parts Cb ... ,Cn of an additive masking.
[0144] More specifically, the second embodiment is described herein as manipulating the m fourth parts. It will be noted, however, that the second embodiment could manipulate a plurality of parts of an additive masking of the number obtained from another masking, for example from the masked number Q(S) and the second multiplicative mask S. Such a mask change is described below for the mask change step (step S1 11) with reference to [Fig.7].
[0145] The second embodiment of the exact division calculation step comprises a mask change sub-step identical to the mask change sub-step (sub-step SS2), described above with reference to [Fig.4].
[0146] The step of calculating the exact division then comprising a sub-step of randomizing the dividend and the number (sub-step SS 104), during which the processor 4 determines a fourth random number X by random drawing, that is to say by truly random drawing or by pseudo-random drawing, then randomizes each sixth part of the masked dividend by applying the fourth random number to the sixth part concerned and each fourth part by applying the fourth random number to the fourth part concerned.
[0147] Typically, the processor 4 draws the fourth random number X uniformly in a closed interval having a lower bound of value 1 and an upper bound of value 2S-1, and for any i ranging from 1 to n, the processor 4 performs a calculation as follows: Ej = E; • X. Furthermore, for any i ranging from 1 to m, the processor performs a calculation as follows: Qj = Q; • X.
[0148] Processor 4 must draw a fourth odd random number X.
[0149] The fourth odd random number makes it possible to secure this second mode of carrying out the exact division calculation step against attacks by auxiliary channels.
[0150] Each sixth part E; can be broken down into one or more word(s) E;[j] of rank j, j representing the weight of the word concerned and E;[0] being the word with the lowest weight of the fifth part E;.
[0151] Similarly, - the fourth part Q; can be decomposed into one or more word(s) Q;[j] of rank j, j representing the weight of the word concerned and Qi[0] being the word of lowest weight of the fourth part Q;; and - for any i ranging from 1 to n, the fifth part C; of the modular inverse can be decomposed into one or more word(s) C;[j] of rank j, j representing the weight of the word concerned and C;[0] being the word of lowest weight of the fifth part C;.
[0152] Each fifth part C; of the modular inverse is broken down into w words, w having the value defined as follows: w — ( p + k - 1 ) > b with k = 2b, k being the word size manipulated by the processor 4. As already described, the size k of a word is for example 8 bits, 16 bits, 32 bits, 64 bits or 128 bits. For example, if k is 8, b is 3.
[0153] The step of calculating the exact division then comprises a sub-step of calculating the inverse of the opposite of a word of least weight (sub-step SS 106) during which the processor 4 calculates an inverse U modulo M a power of 2, of the opposite of the sum of the words of least weight of the fourth randomized parts. The processor 4 therefore obtains the inverse U whose value is defined as follows: y _ ) * 111 ld M TyPicluement' M a For value 2k, k being the size of word manipulated by the processor 4.
[0154] As already described, the calculation of an inverse modulo a power of 2 can be done according to techniques known to those skilled in the art, for example according to the technique described at the end of section 4 of the document “Tudor Jebelean: An Algorithm for Exact Division. J. Symb. Comput. 15(2): 169-180 (1993)”.
[0155] The step of calculating the exact division then comprises sub-steps of initializing a first index, initializing a second index, and calculating a fifth part word, respectively identical to the sub-steps of initializing a first index (sub-step SS8), initializing a second index (sub-step SS 10) and calculating a fifth part word (sub-step SS 12) described above with reference to [Fig.4].
[0156] The step of calculating the exact division then comprises a sub-step of initializing a third index (sub-step SS113) during which the processor 4 initializes an integer v to the value 1.
[0157] The step of calculating the exact division then comprises a sub-step of updating a sixth part (sub-step SS 114) during which the processor 4 updates the sixth part E; as follows: E; = Ej - Q • Cs [ j].
[0158] The processor 4 then determines, in a third test sub-step (step SS115), whether the integer reaches the value m.
[0159] If not, the integer v is incremented by 1 in a third incrementation sub-step (sub-step SS116) and the method loops to the sub-step of updating a sixth part (sub-step SS114).
[0160] If yes at the third test sub-step (sub-step SS115), the processor modifies a sixth part, at a sub-step of modifying a sixth part (sub-step SS117), as follows: Ej = E; > k.
[0161] The step of calculating the exact division then comprises a first test sub-step identical to the first test sub-step (sub-step SS 16) described above with reference to [Fig.4].
[0162] If not, in the first test sub-step (sub-step SS 16), the integer i is incremented by 1 in a first incrementation sub-step identical to the first incrementation sub-step (sub-step SS20) described with reference to [Fig.4] and the method loops to the sub-step of calculating a fifth part word (sub-step SS12).
[0163] If yes in the first test sub-step (sub-step SS16), the processor then determines, in a second test sub-step identical to the second test sub-step (sub-step SS 18) described with reference to FIG. 4, whether the integer ja reaches the value w - 1.
[0164] If not, in the second test sub-step, the integer j is incremented by 1 in a second increment sub-step identical to the second increment sub-step (sub-step SS22) described with reference to [Fig.4] and the method loops to the sub-step of initializing a second index (sub-step SS10) to perform a next round.
[0165] Thus, the method implements n ' w sub-steps of calculating a fifth part word (sub-step SS 12), n ' w sub-steps of modifying a sixth part (sub-step SS 117), and n ' w ' m sub-steps of updating a sixth part (sub-step SS 114).
[0166] If yes in the second test sub-step (sub-step SS18), the step of calculating the exact division of the dividend by the number (step S14) ends.
[0167] A person skilled in the art will understand that the sub-steps of the exact division calculation step can be executed in other orders provided that each sub-step has the elements necessary for its execution.
[0168] According to an example, the sub-step of initializing a first index (sub-step SS8) can be executed before the sub-step of calculating the inverse of the opposite of a least significant word (sub-step SS 106) and / or the sub-step of randomizing the dividend and the number (sub-step SS 104) and / or the sub-step of changing the mask (sub-step SS2).
[0169] The embodiment of the step of calculating the exact division, described with reference to [Fig.5], executes the turns, i.e. the iterations, of each loop with an index that increments at each turn. Those skilled in the art will understand that the index i and / or the index v can be handled differently as long as all the values of the index concerned are traversed by executing the turns of the loop concerned.
[0170] Typically, the exact division computation step may be adapted to perform the n ' w sub-steps of computing a fifth-part word in a different order, with each iteration using a different value of the integer pair i,j. For example, the person skilled in the art may initialize the integer i with the value n in the substep of initializing a second index (substep SS10), initialize the integer j with the value 0 in the substep of initializing a first index (substep SS8), replace the first increment substep (substep SS20) with a first decrement substep that decrements the integer i by 1, determine in the first test substep (substep SS16) whether the integer ia reaches 1, and determine in the second test substep (substep SS 18) whether the integer ja reaches w - 1.
[0171] Furthermore, the exact division calculation step may be adapted to perform the n • w • m sixth part update substeps (substep SS 114) in a different order, with each iteration using a different value of the integer v for a given pair of integers i,j. For example, the person skilled in the art may initialize the integer v with the value m in the third index initialization substep (substep SS 113), replace the third increment substep (substep SS 116) with a third decrement substep that decrements the integer v by 1, and determine in the third test substep (substep SS 115) whether the integer will reach 1.
[0172] A masked implementation of an operation, or algorithm, producing a result equal to applying said operation or algorithm to operands, is an implementation that manipulates said operands in masked form to produce the result also in masked form, without ever manipulating the operands or the result in unmasked form.
[0173] The invention makes it possible to calculate in masked form the modular inverse of the number Q in the ring of integers modulo the given module P, that is to say without manipulation of the number, the given module and the modular inverse, in unmasked form.
[0174] The invention makes it possible to replace a modular reduction operation of the number modulo the given module, said modular reduction operation having to be in masked form by: - a modular reduction of a first data item modulo the public module, the first data item and the public module being manipulated in unmasked form, and - a modular inversion of the other masked module modulo the masked number, the other masked module and the masked number being manipulated as such, i.e. the other masked module and the masked number not being themselves masked to be manipulated, and - an exact division in hidden form, that is, manipulating the dividend, the divisor and its result in hidden form.
[0175] Thus, the method described with reference to Figures 3 to 5 does not require the hidden implementation of the modular reduction and modular inversion operations. Instead, the method allows the use of the hidden implementation of an exact division.
[0176] The invention performs the following calculation securely: [-[(P(R))'' ■ R mod (QJ • P + 1 mod n] / Q-
[0177] This calculation can also be noted: [-[(P- R)4 • R mod (Q ■ S)] • P+ 1 mod N] / Q;
[0178] By definition of the modular inverse, there exists a such that: Q - [Q'1 mod P] = 1 + aP-
[0179] When the number Q is multiplied by the second multiplicative mask S, still according to the definition of the modular inverse, there exists [3 such that: [ ( Q • S)4 mod P] • S= [Q*1 mod P] + [3 ■ P-
[0180] If we multiply this last equation by the number Q over the integers, there exists [3 such that:Q. [(QS) 4modP] SQ- [Q4modP]+(3-PQ-
[0181] We have seen that: Q. [Q'hnodP] = 1 +a ■ P-We therefore have: Q - [(QS)4modP] -S = 1+aP + pP Q-
[0182] Now we have Q . [ Q-! mod P ] = 1 + a • P. Therefore 1 + a ■ P is strictly greater than 0 and strictly less than PQ, that is to say strictly less than N.
[0183] Thus when we reduce q q. $y> mo(j pj . g- 1 + a • P+ p • P - Q By N' we obtain: q (q . gy1 mo{] p] • s) mod N = 1 + a • P = Q • [ Q4 mod P],
[0184] When we express the inverse of Q • S modulo P by the inverse of P modulo Q • S, we have: Q.[ (Q ■ S)4 mod P] • S = P- Q • S- [P4 mod (Q- S) ] • P +1-
[0185] We therefore have: (PQS-[P1 mod (QS)] P+l) modN= Q - [Q4modP].
[0186] Now P ■ Q is the public module N, we therefore have the following equality: ( - [P1 mod (QS) ] P+ 1) mod N - Q- [Q4 mod P].
[0187] Finally, when we multiply the given module P by the first applicative mask R, we obtain: ( - [P"1 mod (Q- S) ] P +1) mod N= ( - [ ( (PR)4- R) mod (Q- S) ] • P+1) mod N
[0188] The following equality is therefore verified: (-[((PR)'-R) mod (Q • S) ] • P+1) modN = Q- [Q'modP].
[0189] The invention therefore obtains the calculation of the modular inverse of a number Q in the ring of integers modulo a given module P by carrying out the following calculation: [-[(W' ■ R mod (Qj • P + 1 mod n] / Q-
[0190] [Fig.6] illustrates in the form of a flowchart the main steps of a method for determining a modular inverse according to a second embodiment of the invention.
[0191] The method of [Fig.6] aims to determine the modular inverse of a number Q in the ring of integers modulo a given module P, the number and the given module being prime numbers, and the given module being masked in the form of n first parts Pb ... ,Pn of an initial masking with n an integer strictly greater than one.
[0192] The size of the given module P is p bits and the size of the number Q is q bits. For example pa for value 1024 and qa also for value 1024. Note however that p can have a different value from that of q.
[0193] The initial masking is here a modular additive masking of modulo 2? with p' an integer greater than or equal to p.
[0194] The method of [Fig.6] is here implemented by the electronic device 2 due to the execution of the computer program instructions stored in the storage entity 6 as indicated above.
[0195] According to a mask change step (step S0), the processor 4 replaces the modular additive masking of 2P module of the given module by an additive masking on the integers.
[0196] Typically, the processor 4 draws n-1 third other random values E'2, ... ,E'n uniformly in a closed interval having a lower bound of value 0 and an upper bound of value 2P - 1, then the processor 4 initializes another data E' i as follows: E'j = Pb Then, for each i going from 2 to n, the processor 4 updates the other data E' i as follows: = E^ - E'j. Then, for each i going from 2 to n, the processor 4 updates the data E' i as follows: E\ = E\ + Pj. Finally, for each i ranging from 2 to n, if Pj + + Pn is a value strictly less than ( i - 1 ) • 2P ' Processor 4 updates the other data as follows: g1 _ g- _ 7P'. Then, for all i ranging from 1 to n, processor 4 updates a first part P; as follows: Pj= Ej.
[0197] Subtracting at least a third other random E'j from the other data E\ before adding to the other data E' 1 the first n- 1 parts P2, ... ,Pn, makes it possible to preserve the confi- dentiality of the given module.
[0198] The comparison of Pi + ■ ■ ■ + P« and Q _ । j . pP is made in a secure manner, for example according to the embodiment described above with reference to [Fig.2].
[0199] At the end of the mask change step (step S0), the first parts are the masked form of the given module according to an additive masking on the integers.
[0200] The method then comprises a step of determining multiplicative masks, a step of determining another masked module, a step of determining a masked number, a step of determining a multiplicative inverse, a step of determining an intermediate inverse, a step of determining second parts of a modular additive masking of a dividend and a step of calculating the exact division of the dividend by the number, respectively identical to the step of determining multiplicative masks (step S2), to the step of determining another masked module (step S4), to the step of determining a masked number (step S6), to the step of determining a multiplicative inverse (step S8), to the step of determining an intermediate inverse (step S10),in the step of determining second parts of a modular additive masking of a dividend (step S12) and in the step of calculating the exact division of the dividend by the number (step S14) described above with reference to [Fig.3].,
[0201] If the number Q is masked in the form of fourth parts of another initial masking, the method of [Fig.6] may further comprise another mask changing step (not shown), during which the processor 4 replaces the other initial masking with an additive masking on the integers.
[0202] For example, if the other initial masking is a modular additive masking of modulus with q' an integer greater than or equal to q, the method of FIG. 6 may further comprise another mask changing step (not shown), during which the processor 4 replaces the modular additive masking of modulus 2q of the number with an additive masking on the integers.
[0203] Typically, the processor 4 draws m-1 fifth random values E”2, ... ,E”m uniformly in a closed interval having a lower bound of value 0 and an upper bound of value 2q -1, then the processor 4 initializes a second other data E”i as follows: E"i = Q Then, for each i ranging from 2 to m, the processor 4 updates the second other data E' ' i as follows: E'^ = E'^ - E”j. Then, for each i ranging from 2 to m, the processor 4 updates the data E' ' i as follows: E'^ = E"j + Q.. Finally, for each i ranging from 2 to m, if Q( + ■ ■ ■ + Qm is a value strictly less than ( i - 1 ) . 2% The processor 4 updates the second other data as follows: J?" — - 2q • Then, for all i ranging from 1 to m, processor 4 updates a fourth part Q; as follows: Q.= E'^.
[0204] Subtracting at least a fifth random number E”; from the second other data E”i before adding to the second other data E' ' i the ni - 1 fourth parts Q2, ... ,Qm, makes it possible to preserve the confidentiality of the number.
[0205] The comparison of Qj + • • • + Qm and 1) ■ 2q is secure, for example according to the embodiment described above with reference to [Fig.2].
[0206] At the end of the other mask changing step, the fourth parts are the masked form of the number according to an additive masking on the integers.
[0207] The other mask changing step is performed within the method before another step of said method needs the fourth parts of the number.
[0208] For example, the other mask changing step is executed before the step of determining a masked number (step S6), and / or before the step of determining second parts of a modular additive masking of a dividend (step S12), and / or before the step of calculating the exact division of the dividend by the number (step S14).
[0209] Thus, the method described with reference to [Fig.6] does not require the hidden implementation of the modular reduction and modular inversion operations. Instead, the method allows the use of the hidden implementation of an exact division.
[0210] A person skilled in the art will understand that the steps of the method for determining a modular inverse described with reference to [Fig.6], can be executed in other orders to the extent that each step has the elements necessary for its execution.
[0211] According to a first example, the step of determining a masked number (step S6) can be executed before the step of determining another masked module (step S4) and after the step of determining multiplicative masks (step S2).
[0212] According to a second example, the step of determining a multiplicative inverse (step S8) can be executed before the step of determining a masked number (step S6) and after the step of determining another masked module (step S4).
[0213] According to a third example, the mask changing step (step S0) can be executed before the step of determining another masked module (step S4) and after the step of determining multiplicative masks (step S2).
[0214] [Fig.7] illustrates in the form of a flowchart the main steps of a method for determining a modular inverse according to a third embodiment of the invention.
[0215] The method of [Fig.7] also aims to determine the modular inverse of a number Q in the ring of integers modulo a given module P, the number and the given module being prime numbers, and the given module being masked in the form of n first parts Pb ... ,Pn of an initial masking with n an integer strictly greater than one.
[0216] The size of the given module P is p bits and the size of the number Q is q bits. For example pa for value 1024 and qa also for value 1024. Note however that p can have a different value from that of q.
[0217] The initial masking here is a multiplicative masking on the two-partition integers. The integer n here therefore has the value 2.
[0218] The method of [Fig.7] is implemented by the electronic device 2 due to the execution of the computer program instructions stored in the storage entity 6.
[0219] The method of [Fig.7] comprises a step of determining multiplicative masks identical to the step of determining multiplicative masks (step S2) described with reference to [Fig.3].
[0220] The method then comprises a step of determining another masked module (step S104), during which the processor 4 determines another masked module P(R) by applying the first multiplicative mask R to the given module P.
[0221] Typically, processor 4 calculates the other hidden module P(R) as follows: P <R,= (P,R) / P2avecPi et P2les premières parties.
[0222] According to a step of determining a masked number (step S106), the processor 4 determines a masked number Q(S) equal to the product of the second multiplicative mask S and the number Q.
[0223] The masked number can be determined by reading a memory of the electronic device 2, for example if the masked number has been previously determined then stored in the storage entity 6. This implementation can be advantageous if the second multiplicative mask has also been recorded in a memory of the electronic device 2 during an operating phase of said electronic device 2 prior to the method described here.
[0224] The masked number can be determined by calculation, for example if the number Q is masked in the form of fourth parts of another initial masking, the fourth parts having previously determined and then stored in the storage entity 6. The other initial masking can be a masking pami an additive masking, a modular additive masking, a multiplication masking and a modular multiplicative masking.
[0225] Typically, when the other initial masking is an m-part multiplicative masking, with m being 2, the processor 4 calculates the masked number Q(S) as with Qi and Q2 the fourth parts.
[0226] The method then comprises a step of determining a multiplicative inverse and a step of determining an intermediate inverse, respectively identical to the step of determining a multiplicative inverse (step S8) and the step of determining an intermediate inverse (step S10) described with reference to [Fig.3].
[0227] The method then comprises a mask change step (step SI 11), during which the processor 4 replaces a multiplicative masking of the given module with an additive masking on the integers.
[0228] During this mask changing step (step S111), the processor 4 determines third parts E'i, E'2 of a preliminary masking of the given module from the first parts of the initial masking of said given module or from the other masked module and the first multiplicative mask. The preliminary masking is here an additive masking on the integers.
[0229] For example, processor 4 draws a third other random number as third part E'2, uniformly in a closed interval having a lower bound of value 0 and an upper bound of value 2P - 1, then processor 4 calculates the third part E' i as follows: - E'2 • R ) / R-
[0230] According to another example, the processor 4 draws a third other random number as a third part E'2, uniformly in a closed interval having a lower bound of value 0 and an upper bound of value 2P- L then the processor 4 calculates the third part E'i as follows: E'j = (Pj-E^ • P->) / P2-
[0231] The method then comprises a step of determining second parts of a modular additive masking of a dividend (step SI 12), during which the processor 4 determines second parts of a modular additive masking of a dividend, the dividend having the value ( - D - P + 1 ) mod N with N a public module of value equal to P • Q, and the determination of each second part comprising the determination of a product of the intermediate inverse and of a third part distinct from the same preliminary masking of the given module, that is to say of the preliminary masking of the given module.
[0232] Typically, for any i ranging from 1 to n, the processor 4 calculates a second part T; of a modular additive masking of a dividend T as follows: Tj = - D • E j + Hj mod N such that ynh mod N = 1 ' The determination of each ^=1 < second part T; therefore includes the determination of a product D • And of the intermediate inverse D and of a third distinct part E'j of the same preliminary masking of the given module P, that is to say of the preliminary masking of the given module P.
[0233] Preferably, for one and only one value of i, H; is 1 and for the other values of i, H; is zero. In this case, the determination of one and only one second part of the masked dividend further comprises an increase by 1 of the product determined modulo the public module.
[0234]
[0235]
[0236]
[0237]
[0238]
[0239]
[0240]
[0241]
[0242] The process is therefore more efficient because it limits the operations necessary to determine the dividend. The public module N may have been recorded in a memory of the electronic device 2 during a phase of operation of the electronic device 2 prior to the method described here. If the public modulus N is not available, the method can calculate the public modulus from the given modulus and the number. According to a first example, the processor 4 calculates the public modulus N as follows: N= (PI'Q(S)) / (P2. . The calculation of Pj • Qf gj and P2 • S before performing the division, allows to preserve the confidentiality of the given module P and the number Q. In a second example, processor 4 calculates the public modulus N as follows: z_ y2 / p, \ then N = Z / S with Z an intermediate result. Sum of the products E'j • Q(Sy i ranging from 1 to 2, allows to preserve the confidentiality of the given module P. In addition, the division by the second multiplicative mask S concerns the result of this sum, which allows to preserve the confidentiality of the number Q. According to a third example, the processor 4 calculates the public modulus N as follows: N= (P(r)'Q(^) / (R ■ S) • calculation of Pçr) ■ and RS before performing the division, allows to preserve the confidentiality of the given modulus P and the number Q. According to a fourth example, if the number Q is masked in the form of 2 fourth parts of a multiplicative masking, the fourth parts having been previously determined then stored in the storage entity 6, the processor 4 calculates the public modulus N as follows: N = ( Pi • Qj ) / ( P2 * Q2 ) ' calculation of P, • Q{ and P2 • Q? before carrying out the division, makes it possible to preserve the confidentiality of the given modulus P and of the number Q. According to a fifth example, still if the number Q is masked in the form of 2 fourth parts of a multiplicative masking, the processor 4 can calculate the public modulus N as follows: _ J^2 ^E'- Q ) PUL Z / Q7 with Z an intermediate result. Summing products Ej ■ Qp i ranging from 1 to 2, makes it possible to preserve the confidentiality of the given modulus P. In addition, the division by the fourth part Q2 relates to the result of this sum, which makes it possible to preserve the confidentiality of the number Q. According to a sixth example, still if the number Q is masked in the form of 2 fourth parts of a multiplicative masking, the processor 4 can calculate the public modulus N as follows: N = ( P(R) • Qx ) / ( R • Q2 ) • The calculation of P(r) ■ Q} and R • Q9 before performing the division, makes it possible to preserve the confidentiality of the given modulus P and of the number Q.
[0243] The method then comprises a step of calculating the exact division of the dividend by the number identical to the step of calculating the exact division of the dividend by the number (step S14) described with reference to [Fig.3].
[0244] It will be noted that if the step of calculating the exact division of the dividend by the number is according to the second embodiment described with reference to [Fig.5], the method of [Fig.7] may comprise an additional step (not shown) during which the processor 4 replaces a multiplicative masking of the number with an additive masking. This step can be carried out in a similar manner to what was described for the mask changing step (step SI 11).
[0245] Thus, the method described with reference to [Fig.7] does not require the hidden implementation of the modular reduction and modular inversion operations. Instead, the method allows the use of the hidden implementation of an exact division.
[0246] A person skilled in the art will understand that the steps of the method for determining a modular inverse described with reference to [Fig.7], can be executed in other orders to the extent that each step has the elements necessary for its execution.
[0247] According to a first example, the step of determining a masked number (step S106) may be executed before the step of determining another masked modulus (step S104) and after the step of determining multiplicative masks (step S2).
[0248] According to a second example, the step of determining a multiplicative inverse (step S8) may be executed before the step of determining a masked number (step S106) and after the step of determining another masked modulus (step S104).
[0249] According to a third example, the mask changing step (step S111) may be executed before the step of determining a masked number (step S106) and after the step of determining another masked modulus (step S104), or before one of the step of determining multiplicative masks (step S2) and the step of determining another masked modulus (step S104).
[0250] The method for determining a modular inverse described with reference to [Fig.7] can be adapted to multiplicative maskings with n shares, n being greater than or equal to 3.
[0251] [Fig.8] illustrates in the form of a flowchart the main steps of a method for determining a modular inverse according to a fourth embodiment of the invention.
[0252] The method of [Fig.8] also aims to determine the modular inverse of a number Q in the ring of integers modulo a given module P, the number and the given module being prime numbers, and the given module being masked in the form of n first parts Pb ... ,Pn of an initial masking with n a strictly greater integer to one.
[0253] The size of the given module P is p bits and the size of the number Q is q bits. For example pa for value 1024 and qa also for value 1024. Note however that p can have a different value from that of q.
[0254] The initial masking here is a modular multiplicative masking of modulo 2? with two shares, with p' an integer greater than or equal to p. The integer na therefore has the value 2 here.
[0255] According to a mask change step (step S100), the processor 4 replaces the modular multiplicative masking of 2P modulus of the given modulus with an additive masking on the integers.
[0256] Typically, the processor 4 begins by replacing the modular multiplicative masking of modulo pP of the given modulo with a modular additive masking of modulo pP.
[0257] For this, the processor 4 draws an intermediate random value R' uniformly in a closed interval having a lower bound of value 0 and an upper bound of value pP' _ ], then the processor 4 calculates a third intermediate data Z' as follows: 2 — niod 2P'- Then the processor 4 calculates two intermediate parts P'i,P'2 as follows: p ( = ( prR-) . Z mod 2P' and P2 = R' • Zmod 2P'
[0258] The two intermediate parts P' i,P'2 are the given module masked in the form of the modular additive masking of module pP'.
[0259] The processor 4 then continues by replacing the modular additive masking of module pP of the given module by the additive masking on the integers.
[0260] For this, the processor 4 draws a third other random number E'2 uniformly in an in closed interval having a lower bound of value 0 and an upper bound of value 2P- 1, then processor 4 calculates a first other data E'i as follows E'{ = P'j - E'2. Then, processor 4 updates the first other data E' 1 as follows: E^ = E'j + P'2. Finally, if P'l + P'2 is a value strictly less than 2P, processor 4 updates the first other data as follows: jr _ _ 2P- Then, for any i ranging from 1 to 2, processor 4 updates a first part as follows: P;= Ej.
[0261] Subtracting at least the third other random number E'2 from the intermediate part P' before adding the intermediate part P'2 to the first other data E'i, makes it possible to preserve the confidentiality of the given module.
[0262] The comparison of P\ + P2 and 9P is made securely, for example according to the embodiment described above with reference to [Fig.2].
[0263] At the end of the mask changing step (step S100), the first parts are the masked form of the given module according to an additive masking on the integers.
[0264] The method then comprises a step of determining multiplicative masks, a step of determining another masked module, a step of determining a masked number, a step of determining a multiplicative inverse, a step of determining an intermediate inverse, a step of determining second parts of a modular additive masking of a dividend and a step of calculating the exact division of the dividend by the number, respectively identical to the step of determining multiplicative masks (step S2), to the step of determining another masked module (step S4), to the step of determining a masked number (step S6), to the step of determining a multiplicative inverse (step S8), to the step of determining an intermediate inverse (step S10),in the step of determining second parts of a modular additive masking of a dividend (step S12) and in the step of calculating the exact division of the dividend by the number (step S14) described above with reference to [Fig.3].,
[0265] If the number Q is masked in the form of fourth parts of another initial masking, the method of [Fig.8] may further comprise another mask changing step (not shown), during which the processor 4 replaces the other initial masking with an additive masking on the integers.
[0266] For example, if the other initial masking is a modular multiplicative masking of modulus with q' an integer greater than or equal to q, the method of FIG. 8 may further comprise another mask changing step (not shown), during which the processor 4 replaces the modular multiplicative masking of modulus 2q of the number with an additive masking on the integers.
[0267] Typically, the processor 4 begins by replacing the modular multiplicative masking of modulus 2q of the number with a modular additive masking of modulus
[0268] For this, the processor 4 draws another intermediate random value R' ' uniformly in a closed interval having a lower bound of value 0 and an upper bound of value pM'_ j, then the processor 4 calculates a fourth intermediate data Z” as follows: — Q mod 7q- Then the processor 4 calculates two other parts in intermediates Q' i,Q'2 as follows: q' = q R" j . z mcK] 2q'and Q2 = R” • Z" mod 2q-
[0269] The other two intermediate parts Q' i,Q'2 are the masked number in the form of the modular additive masking of module '•
[0270] Processor 4 then continues by replacing the modular additive masking of the pcl module of the number with the additive masking on the integers.
[0271] Typically, the processor 4 draws a fifth random number E”2 uniformly in a closed interval having a lower bound of value 0 and an upper bound of value 2q- 1, then processor 4 calculates a second other data E”i as follows: E”j — Q' - E"2. Then processor 4 updates the second other data E' ' i as follows: E"i = E"। 4- Q' Finally, if Q\ 4- Q' is a value strictly less than , processor 4 updates the second other data as follows: g" _ g» _ 2q . Then, for all i ranging from 1 to 2, processor 4 updates a fourth part as follows: Q(= E".
[0272] Subtracting at least the fifth random number E”2 from the other intermediate part Q\ before adding the other intermediate part Q'2 to the second other data E”i, makes it possible to preserve the confidentiality of the number.
[0273] The comparison of + Q'? and qA is made securely, for example according to the embodiment described above with reference to [Fig.2].
[0274] At the end of the other mask changing step, the fourth parts are the masked form of the number according to an additive masking on the integers.
[0275] The other mask changing step is performed within the method before another step of said method needs the fourth parts of the number.
[0276] For example, the other mask changing step is executed before the step of determining a masked number (step S6), and / or before the step of determining second parts of a modular additive masking of a dividend (step S12), and / or before the step of calculating the exact division of the dividend by the number (step S14).
[0277] Thus, the method described with reference to [Fig.8] does not require the hidden implementation of the modular reduction and modular inversion operations. Instead, the method allows the use of the hidden implementation of an exact division.
[0278] A person skilled in the art will understand that the steps of the method for determining a modular inverse described with reference to [Fig.8], can be executed in other orders to the extent that each step has the elements necessary for its execution.
[0279] According to a first example, the step of determining a masked number (step S6) can be executed before the step of determining another masked module (step S4) and after the step of determining multiplicative masks (step S2).
[0280] According to a second example, the step of determining a multiplicative inverse (step S8) can be executed before the step of determining a masked number (step S6) and after the step of determining another masked module (step S4).
[0281] According to a third example, the mask changing step (step S100) can be executed before the step of determining another masked module (step S4) and after the step of determining multiplicative masks (step S2).
[0282] The method of determining a modular inverse described with reference to [Fig.8] can be adapted to modular multiplicative maskings with n shares, n being greater than or equal to 3.
[0283] The electronic device 2 may implement a method for generating an RSA CRT key comprising a method as described above. Typically, the electronic device 2 may implement a method for generating an RSA CRT key comprising a modular inverse determined by a method as described above, in particular with reference to a figure among figures 3, 6, 7 and 8.
Claims
Claims
1. Method for determining a modular inverse of a number Q in the ring of integers modulo a given module P, the number and the given module being prime numbers, the given module being masked in the form of first parts of an initial masking, the method being implemented by an electronic device (2) and the method comprising the following steps: - Determination (S2), preferably by random selection, of a first multiplicative mask and a second multiplicative mask which are not harmed and prime to each other, - Determination (S4, S104) of another masked module by applying the first multiplicative mask to the given module P, - Determination (S6, S106) of a masked number equal to the product of the second multiplicative mask and the number Q,- Determination (S8) of a multiplicative inverse of the other masked module then determination (S 10) of an intermediate inverse D result of a multiplication of the multiplicative inverse of the other masked module by the first multiplicative mask modulo the masked number, - Determination (S12,S112) of second parts of a modular additive masking of a dividend, the dividend having the value ( - D • P + 1 ) mod N with N a public module of value equal to P • Q, and the determination of each second part comprising the determination of a product of the intermediate inverse and a third distinct part of the same preliminary masking of the given module, - Calculation (S 14) of the exact division of the dividend by the number, the modular inverse being the result of the exact division, the dividend, the modular inverse and the number being manipulated in masked form.,
2. A method according to the preceding claim wherein the initial masking is a masking among an additive masking, a modular additive masking, a multiplicative masking and a modular multiplicative masking.
3. A method according to any preceding claim wherein the preliminary masking is additive masking.
4. A method according to any preceding claim wherein the third parts are the first parts.
5. A method according to any preceding claim wherein determining one and only one second part of the dividend hidden further includes an increase of 1 of the product determined modulo the public module.
6. A method according to any preceding claim wherein the exact division comprises replacing (SS2) the modular additive masking of the dividend with an additive masking.
7. A method according to any preceding claim wherein the calculation of the exact division manipulates the masked number and the second multiplicative mask, the second multiplicative mask being odd.
8. A method according to any preceding claim further comprising calculating the public modulus from the given modulus and the number.
9. A method of generating an RSA CRT key comprising a method according to one of the preceding claims.
10. Computer program comprising instructions executable by a processor and adapted to implement a method according to any one of the preceding claims, when these instructions are executed by the processor.
11. Electronic device for determining a modular inverse of a number Q in the ring of integers modulo a given module P, the number and the given module being prime numbers, the given module being masked in the form of first parts of an initial masking, and the electronic device comprising: - a block for determining multiplicative masks configured to determine, preferably by random selection, a first multiplicative mask and a second multiplicative mask that are not nullified and prime to each other, - a block for determining another masked module configured to determine another masked module by applying the first multiplicative mask to the given module P, - a block for determining a masked number configured to determine a masked number equal to the product of the second multiplicative mask and the number Q,- an inversion block configured to determine a multiplicative inverse of the other masked module and then determine an intermediate inverse D resulting from a multiplication of the multiplicative inverse of the other masked module by the first multiplicative mask modulo the masked number, - a dividend determination block configured to determine, second parts of a modular additive masking of a dividend, the dividend having the value ( - D • P + 1 ) mod N with N a public module of value equal to P • Q, and the determination of each second part comprising the determination of a product of the intermediate inverse and a third part distinct from the same preliminary masking of the given module, - an exact division block configured to calculate the exact division of the dividend by the number, the modular inverse being the result of the exact division, the dividend, the modular inverse and the number being manipulated in hidden form.
Citation Information
Patent Citations
Determination of a Modular Inverse
US20080201398A1
Protecting modular inversion operation from external monitoring attacks
WO2019079048A1